CVE-2022-35131: XSS
Published Jul 25, 2022
·Updated
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
Affected Software
1 affected component
Joplinapp Joplin=2.8.8
Event History
Jul 25, 2022
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-35131?
CVE-2022-35131 is a vulnerability in Joplin v2.8.8 that allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
2
How severe is CVE-2022-35131?
CVE-2022-35131 has a severity rating of critical with a value of 9.
3
What software versions are affected by CVE-2022-35131?
Joplin v2.8.8 is affected by CVE-2022-35131.
4
How can I fix CVE-2022-35131?
To fix CVE-2022-35131, upgrade to Joplin v2.9.1 or later.
5
Where can I find more information about CVE-2022-35131?
You can find more information about CVE-2022-35131 at the following references: http://joplin.com, https://github.com/laurent22/joplin/releases/tag/v2.9.1, https://github.com/ly1g3/Joplin-CVE-2022-35131